Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

Novell NetWare Encoded Slash Directory Traversal Vulnerability

A vulnerability has been reported in some versions of Novell NetWare. This issue lies in the handling of some HTTP requests when a web server uses Perl as a handler.

Reportedly, a directory traversal attack is possible. This is the result of an error in the handling of the URL encoded '\' character, which is encoded as '%5C'. Full technical details are not available.

This issue has been reported in versions of NetWare using Perl 5.003. Reportedly, systems with Perl 5.6 installed are not vulnerable to this issue.







 

Privacy Statement
Copyright 2008, SecurityFocus